Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 1Objective 3

Malware and AI Assisted Investigations GCIH Practice Questions (Page 3)

Part of the Incident Response and Investigation domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
7concepts

Questions 11–15

  1. 11expert · hard

    A malware analyst is preparing to analyze a sample that is believed to be part of a targeted attack against a financial institution. The sample contains what appears to be customer account numbers. The analyst wants to use an AI-based tool that requires uploading the sample to a cloud service. The organization has a strict policy that customer data must not leave the organization's premises. What is the best course of action?

    Select an answer first
  2. 12expert · hard

    An incident response team is using an AI-based system that automatically prioritizes incidents based on potential business impact. During a major incident, the system prioritizes a low-impact incident over a high-impact one because the low-impact incident has a higher confidence score. What is the best way to handle this?

    Select an answer first
  3. 13expert · hard

    A malware analyst is using an AI-based tool that automatically generates YARA rules from malware samples. The tool has access to a repository of malware samples that includes sensitive data from a breach. The analyst wants to share the generated YARA rules with a public threat intelligence platform. What is the most important consideration?

    Select an answer first
  4. 14application · medium

    A security analyst receives a suspicious executable from an internal user. The file is not yet detected by antivirus. The analyst needs to determine whether the binary is packed or obfuscated before deciding to run it in a sandbox. Which static analysis step would provide the most direct evidence of packing?

    Select an answer first
  5. 15foundation · easy

    Which legal consideration is most relevant when using AI tools to analyze malware samples?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.